SOYAL 701 Client 9.0.1 – Insecure Permissions
# Exploit Title: SOYAL 701 Client 9.0.1 - Insecure Permissions
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: SOYAL 701 Client 9.0.1 - Insecure Permissions
# Exploit Title: KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Command Injection (Authenticated)
# Exploit Title: KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Authentication Bypass
# Exploit Title: KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Hard coded Credentials Shell Access
# Exploit Title: KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Remote Code Execution
# Exploit Title: KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Factory Reset (Unauthenticated)
# Exploit Title: KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Device Reboot (Unauthenticated)
# Exploit Title: KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Config Download (Unauthenticated)
# Exploit Title: Online News Portal 1.0 - 'name' SQL Injection
# Exploit Title: Online News Portal 1.0 - 'Multiple' Stored Cross-Site Scripting
# Exploit Title: VFS for Git 1.0.21014.1 - 'GVFS.Service' Unquoted Service Path
# Title: VestaCP 0.9.8 - 'v_interface' Add IP Stored XSS
# Exploit Title: rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (1)
# Exploit Title: SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (1)
# Title: Hestia Control Panel 1.3.2 - Arbitrary File Write
# Exploit Title: WoWonder Social Network Platform 3.1 - 'event_id' SQL Injection
# Exploit Title: VestaCP 0.9.8 - File Upload CSRF
# Exploit title: FastStone Image Viewer 7.5 - .cur BITMAPINFOHEADER 'BitCount' Stack Based Buffer Overflow (ASLR & DE...
# Exploit Title: Alphaware E-Commerce System 1.0 - Unauthenicated Remote Code Execution (File Upload + SQL injection)
# Exploit Title: GeoGebra Graphing Calculator 6.0.631.0 - Denial Of Service (PoC)
# Exploit Title: GeoGebra Classic 5.0.631.0-d - Denial of Service (PoC)
# Exploit Title: GeoGebra CAS Calculator 6.0.631.0 - Denial of Service (PoC)
# Exploit Title: Zenario CMS 8.8.53370 - 'id' Blind SQL Injection
# Exploit Title: MagpieRSS 0.72 - 'url' Command Injection and Server Side Request Forgery
# Exploit Title: rConfig 3.9.6 - 'path' Local File Inclusion (Authenticated)
# Exploit Title: QNAP QVR Client 5.0.0.13230 - 'QVRService' Unquoted Service Path
# Exploit Title: Realtek Wireless LAN Utility 700.1631 - 'Realtek11nSU' Unquoted Service Path
# Exploit Title: eBeam education suite 2.5.0.9 - 'eBeam Device Service' Unquoted Service Path
# Exploit Title: Interactive Suite 3.6 - 'eBeam Stylus Driver' Unquoted Service Path
# Exploit Title: openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scripting
# Exploit Title: Sonlogger 4.2.3.3 - SuperAdmin Account Creation / Information Disclosure
import requests
# Exploit Title: Monitoring System (Dashboard) 1.0 - 'uname' SQL Injection
# Exploit Title: Monitoring System (Dashboard) 1.0 - File Upload RCE (Authenticated)
# Exploit Title: Vembu BDR 4.2.0.1 U1 - Multiple Unquoted Service Paths
# Exploit Title: NuCom 11N Wireless Router 5.07.90 - Remote Privilege Escalation
# Exploit Title: MyBB OUGC Feedback Plugin 1.8.22 - Cross-Site Scripting
# Exploit Title: CouchCMS 2.2.1 - XSS via SVG file upload
# Exploit Title: Microsoft Exchange 2019 - SSRF to Arbitrary File Write (Proxylogon)
# Exploit Title: Nsasoft Hardware Software Inventory 1.6.4.0 - 'multiple' Denial of Service (PoC)
# Title: Atlassian JIRA 8.11.1 - User Enumeration
# Golden FTP Server 4.70 - 'PASS' Buffer Overflow (2)
# Exploit Title: FreeLAN 2.2 - 'FreeLAN Service' Unquoted Service Path
# Exploit Title: Sandboxie Plus v0.7.2 - 'SbieSvc' Unquoted Service Path
# Exploit Title: bVPN 2.5.1 - 'waselvpnserv' Unquoted Service Path
# Exploit Title: Hotel and Lodge Management System 1.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: Pingzapper 2.3.1 - 'PingzapperSvc' Unquoted Service Path
# Exploit Title: Joomla JCK Editor 6.4.4 - 'parent' SQL Injection (2)
# Exploit Title: GLPI 9.5.3 - 'fromtype' Unsafe Reflection